I'd say that to be fair in comparison, you should probably account for the severity of each vulnerability as well, esp. compared to the response time. It's a serious problem if a zero-day remote vulnerability with an exploit in the wild is fixed in 42 days but not so if a minor potential local DoS is not fixed yet.
Debian, for example¹, is frequently postponing minor vulnerabilities to stable point releases instead of pushing them as security updates.